Exploits of the Java Runtime Environment (JRE) have been extensively used in drive-by-download toolkits such as Blackhole and Red Kit. New vulnerabilities discovered in 2013, such as CVE-2013-1493 and CVE-2013-0422, are popular, and we still see lots of older exploits such as CVE-2012-1723, CVE-2012-4681, and CVE-2012-0507. These vulnerabilities are already fixed in the latest JRE. Read more…
Tags: CVE 2012-1723, CVE-2013-0422, CVE-2013-1493, exploit, jar, java, Java Runtime Environment
Since last week, we have seen many specially crafted files exploiting CVE-2012-0158, a vulnerability in MSCOMCTL.OCX in Microsoft Office and some other Microsoft products. This exploit can be implemented in a variety of file formats, including RTF, Word, and Excel files. We have already found crafted RTF and Word files in the wild. In the Read more…
Tags: CVE-2012-0158, exploit, OLE, RTF
The fake-alert families (bogus or rogue anti-virus software) are one of the most prevalent threats we face, and we see lots of new variants everyday. The threat is expanding constantly. For example, a couple of weeks ago, we observed MacDefender/MacProtector, which targeted Mac users, in addition to the usual attacks against Windows users. Today, I’m Read more…
JustSystem has released an advisory for a new vulnerability discovered in their Japanese word processor called “Ichitaro” in September. The patch of this vulnerability has already been published by the vendor. McAfee Labs has been observing a number of crafted jtd files (detected as Exploit-TaroDrop.i trojan) exploiting this vulnerability since mid-September. Many types of backdoor trojan Read more…
Tags: McAfee Labs, vulnerability
The other day, I came across a malware that attempts to hide its infection not in that technical but in the very unique way. “Muster” is a family of backdoor which has been using help files for hiding themselves. The help files or “.hlp” files are data files designed to be viewed with Microsoft WinHelp Read more…
Hello, it is now April 1st for at least Asia Pacific and Europe. We’ve been blogging and posting various resources about ways to protect against the Conficker worm up to its “activation day”:  ”More Comments Regarding Conficker“  ”W32/Conficker: Much Ado About Nothing?“. The day has finally arrived. McAfee Avert Labs has been closely monitoring Conficker-related threats and, Read more…
For years, the Japanese word processor Ichitaro has been attacked by malware authors exploiting flaws in the application. So it is no surprise that in the last week we discovered in the wild specially crafted Ichitaro document files exploiting a new vulnerability. This time, the crafted file (detected as the Exploit-TaroDrop.g Trojan) drops and runs Read more…
– Update Feb 24, 10:15 PDT – Microsoft has released a security advisory for this issue (CVE-2009-0238): http://www.microsoft.com/technet/security/advisory/968272.mspx Many versions of Excel are vulnerable, including 2000, 2002, 2003, 2007, 2004/2008 for Mac, Excel Viewer/Excel Viewer 2003.  – A Trojan exploiting an unpatched Microsoft Excel vulnerability has been reported from the field. McAfee Avert Labs has confirmed Read more…
Shortcuts, or LNK files, are small binary files which have the path to an applications, sometimes with optional parameters. These files are used for running applications and are placed on folders where they are easy to access by users on such places as Desktops, and Application Launchers. The LNK files are also placed within the Read more…
Today a new downloader trojan is being spammed widely. This spam message arrives as a reply to the victim’s query of asking for the wire transfer. When users run the file “bank_statement.scr” in the attachment zip file, it downloads the BackDoor-DSG trojan, while in the background it downloads an innocent pdf document from a legit Read more…
Posts by Shinsuke Honjo